Incident Response

Zepp Health attaches great importance to security issues and welcomes all security researchers to report potential security vulnerabilities, helping us improve the security of our smartwatches and IoT devices (software, hardware, firmware).

Vulnerability Response and Disclosure Process

Our structured approach to handling reported vulnerabilities ensures timely and effective resolution.

Recipient

Monitor and assign received vulnerabilities in a timely manner

Verification

Verify the vulnerability and confirm the exploitability and impact

Solution Development

Provide effective fix solutions or risk remediation measures

Affected Scope Confirmation

Investigate and confirm the complete scope of affected products

Publish Advisory

Review and publish the security advisory for the security vulnerability

Reporting a Vulnerability

Mailbox

Submit your findings

Report discovered security vulnerabilities to our dedicated security team.

Your report should contain at least:

  • Your organization and contact information
  • Products and versions affected
  • Description of the potential vulnerability
  • Information about known exploits
  • Disclosure plans
  • Additional information
Attention: Zepp Health does not tolerate any activity that may interfere with legitimate users or violate applicable regulations. The following activities are prohibited:
  • Modification or destruction of data
  • Service disruption or degradation (e.g. DoS)
  • Disclosure of personal, proprietary or financial information
Response Time

48-hour response

Zepp Health will respond within 48 hours to the vulnerabilities you submit.

Actual response time may vary depending on the risk level and complexity of the vulnerability.

Escalation and Decision Making

Escalation criteria are defined based on incident severity and impact to ensure critical vulnerabilities receive appropriate management attention without undue delay.

Escalation Criteria

Escalation may be initiated when any of the following conditions are met:

  • Confirmed active exploitation
  • Significant impact to users or services
  • Widespread product exposure
  • Regulatory reporting obligations
  • Inability to remediate within defined SLA timelines
Decision Authority

Critical decisions — including public communication and regulatory reporting — are made by authorized roles based on predefined thresholds. Acknowledgement and communication activities may be prioritized or accelerated for vulnerabilities assessed as critical, actively exploited, or associated with significant customer or operational impact.

Timeliness: Escalation may be initiated where acknowledgement timelines are exceeded or communication activities are delayed for critical vulnerability reports. Escalation paths ensure that critical vulnerabilities and significant cybersecurity incidents are brought to the attention of appropriate management levels without undue delay.
Documentation: Escalation records, decisions, and approvals are documented within the vulnerability management process. Escalation procedures support management awareness and corrective actions where communication timelines, acknowledgement expectations, or disclosure coordination activities are delayed or not achieved as expected.